Ajenti
cpe:2.3:a:ajenti:ajenti:*:*:*:*:*:*:*
- < 2.2.15
A vulnerability exists in Ajenti versions prior to 2.2.15, allowing an authenticated user to install custom packages without superuser privileges. This issue arises in the ajenti-panel component when the auth_users plugin authentication method is used.
Exploitation of this vulnerability could lead to unauthorized package installations, potentially allowing for the introduction of malicious software or modifications to the server environment.
Users are advised to upgrade to Ajenti version 2.2.15 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.